Red Hat Wildfly-Core vulnerabilities

4 known vulnerabilities affecting red_hat/wildfly-core.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2021-3644LOWCVSS 3.3vFixed in 16.0.1.Final, 17.0.0.Final and later.2022-08-26
CVE-2021-3644 [LOW] CWE-200 CVE-2021-3644: A flaw was found in wildfly-core in all versions A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality
cvelistv5
CVE-2020-25689MEDIUMCVSS 6.5vup to 21.0.0.Final2020-11-02
CVE-2020-25689 [MEDIUM] CWE-401 CVE-2020-25689: A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tr A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat
cvelistv5nvd
CVE-2019-14838MEDIUMCVSS 4.9vbefore 7.2.5.GA2019-10-14
CVE-2019-14838 [MEDIUM] CWE-284 CVE-2019-14838: A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Dep A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
cvelistv5nvd
CVE-2018-10934MEDIUMCVSS 5.4v7.1.6.CR1v7.1.6.GA2019-03-27
CVE-2018-10934 [MEDIUM] CWE-79 CVE-2018-10934: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
cvelistv5nvd